Suspicious
Suspect

6bf4eab31555e393f42288f87cca0946

PE Executable
MD5: 6bf4eab31555e393f42288f87cca0946
Size: 884.23 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 6bf4eab31555e393f42288f87cca0946
Sha1 883c35e89391c9c8aacea0c9286f507e85ba3797
Sha256 c7d8e756ffc76fd688a418364004171305a080b8d77f4dec4cdb8b891b2a1848
Sha384 fb0d9bb330be794e27afe58a31a7803fd327d537e9fb2387fa3da9785adf382004da95bdcbb741eba581d38ec657122b
Sha512 ce061faa96c944c4079cf21782ccdcc339a1e4f63fdd56f78c7dcb712c44fc1e0212684b5ca47c8b9e03200ce0c1325f61d598b9bc7d5f337bb26f994b78645d
SSDeep 12288:Hj73Wrt3DMcUxJr9qM8p/hliW08KjvJaitjq24ZqGjlxtYRwNV00VqbdvnJ5hG5U:Hj7MMjVqxp/uWmjv3w2ktFNqbFwsf8G
TLSH EB1512683216D80BC52287744A71F2B817B96E9AF111D697AFE83E9FBCF5B044D20193
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
EstudoTaskool.frmCadastro.resources
$this.Icon
[NBF]root.IconData
EstudoTaskool.Views.frmListaUsuario.resources
EstudoTaskool.Properties.Resources.resources
WAOn
[NBF]root.Data
[NBF]root.Data-preview.png
foto
[NBF]root.Data
[NBF]root.Data-preview.png
logo
[NBF]root.Data
Database.DBModel.csdl
Database.DBModel.msl
Database.DBModel.ssdl
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xD4800 size 13832 bytes
Info
PDB Path: ?
Module Name
XefB.exe
Full Name
XefB.exe
EntryPoint
System.Void EstudoTaskool.Program::Main()
Scope Name
XefB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XefB
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
144
Main Method
System.Void EstudoTaskool.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void EstudoTaskool.FrmPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
XefB.exe
Full Name
XefB.exe
EntryPoint
System.Void EstudoTaskool.Program::Main()
Scope Name
XefB.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
XefB
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
144
Main Method
System.Void EstudoTaskool.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void EstudoTaskool.FrmPrincipal::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
[Authenticode]_a32ace3a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:0
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
EstudoTaskool.frmCadastro.resources
$this.Icon
[NBF]root.IconData
EstudoTaskool.Views.frmListaUsuario.resources
EstudoTaskool.Properties.Resources.resources
WAOn
[NBF]root.Data
[NBF]root.Data-preview.png
foto
[NBF]root.Data
[NBF]root.Data-preview.png
logo
[NBF]root.Data
Database.DBModel.csdl
Database.DBModel.msl
Database.DBModel.ssdl
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙